← back
CVE-2009-2532observed exploitation

CVE-2009-2532

57Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actepss 62%
from disclosure to weapon307 days
Published on NVDOct 14
1st PoC+307d
VulnCheck+2806d
exploitation probability
62%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SMBv2 packet to the Server service, aka "SMBv2 Command Value Vulnerability."
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.